Move Home Organisation CIC · Authentication Profile

Movehome Org Authentication

Authentication

Move Home Organisation CIC secures its APIs with none and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).

Real EstatePropertyLettingsProperty SalesAgentsA2AMCPAgent-NativeAgent RegistryNon-ProfitOpen SourceRAIA ProtocolUnited Kingdom
Methods: none, oauth2 Schemes: 2 OAuth flows: clientCredentials API key in:

Security Schemes

Anonymous none
OAuth2ClientCredentials oauth2
· flows: clientCredentials

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/movehome-org-raia-portal-feed-openapi.yaml
docs:
- https://movehome.org/skills.md
- https://github.com/MoveHome/MoveHome.Org/blob/main/docs/raia-portal-feed-api.md#3-authentication
- https://github.com/MoveHome/MoveHome.Org/blob/main/docs/raia-a2a-api.md
summary:
  types:
  - none
  - oauth2
  oauth2_flows:
  - clientCredentials
  api_key_in: []
  bearer: true
  credential_classes: 2
  headline: >-
    Two postures on one host. The agent-facing surfaces — the A2A agent (all three skills, including the
    create_enquiry write), both MCP servers and the A2A-registry REST API — are ANONYMOUS: no key, no token,
    no signup ("Auth: none (anonymous)", skills.md), with per-IP rate limits as the only gate. The inbound
    RAIA Portal Feed API is OAuth 2.0 client credentials: the MoveHome operator issues a client_id and
    client_secret out-of-band, bound to one agent, a default branch and an allowed scope set; POST
    https://movehome.org/oauth/token (HTTP Basic or form fields) mints a 1-hour HS256 Bearer JWT scoped to
    feed.read / feed.write / products.write. No OIDC, no API keys, no RFC 8414/9728 discovery documents.
schemes:
- name: Anonymous
  type: none
  surfaces:
  - https://movehome.org/api/a2a (A2A JSON-RPC — search_properties, get_property, create_enquiry)
  - https://movehome.org/mcp and https://movehome.org/api/mcp (MCP, read-only)
  - https://movehome.org/api/registry/mcp (MCP, read-only)
  - https://movehome.org/api/registry/v1/* (REST — reads AND the register / re-sync / flag writes)
  - https://movehome.org/api/enquire (website enquiry form POST)
  controls:
  - per-IP rate limits (60/min agent surfaces; 5/min enquiry; 10/min registry register; 5/min flag)
  - create_enquiry duplicate suppression (same email + listing within ~10 min) and a per-email hourly cap
  - registry registration validates the submitted card by fetching it from the declared well-known URI
  observed:
  - 'POST /api/a2a message/send with no credentials -> 200 completed Task (2026-09-19)'
  - 'POST /mcp tools/list with no credentials -> 200, 2 tools'
  - 'POST /api/registry/mcp tools/list with no credentials -> 200, 3 tools'
  - 'GET /api/registry/v1/agents?limit=3 -> 200'
  note: >-
    The agent card declares no securitySchemes, which is accurate. CORS is open on every anonymous surface,
    so browser-hosted agents can call them directly.
- name: OAuth2ClientCredentials
  type: oauth2
  surfaces:
  - https://movehome.org/api/raia/portal/v1/* (every operation except GET /healthz)
  flows:
  - flow: clientCredentials
    tokenUrl: https://movehome.org/oauth/token
    tokenUrl_in_spec: https://feed.example.com/oauth/token
    scopes: 3
    scopes_list: [feed.read, feed.write, products.write]
  client_authentication: HTTP Basic (client_id:client_secret) or form fields client_id / client_secret; grant_type must be client_credentials
  token:
    format: JWT
    alg: HS256
    ttl_seconds: 3600
    header: 'Authorization: Bearer <access_token>'
    response: '{ access_token, token_type: "Bearer", expires_in: 3600, scope }'
    scope_handling: requested scope is intersected with the credential's allowed_scopes; omit scope to receive all allowed scopes
    verification: server-side only — HS256 with a shared secret; the published JWKS (/.well-known/jwks.json) is empty, so third parties cannot verify these tokens (the RAIA spec recommends RS256 for that reason)
  credential_issuance:
    how: out-of-band by the MoveHome operator (scripts/portal-create-credential.cjs in the provider's repository); the secret is shown once
    contact: admin@movehome.org
    signup: none — no self-service developer portal
  rate_limit: token endpoint 10 requests/min per client; API 60/min per credential per endpoint group
  observed:
  - 'POST /oauth/token grant_type=client_credentials (no client) -> 401 application/problem+json {"type":"https://movehome.org/errors/unauthorized","detail":"Missing client_id / client_secret. Use HTTP Basic or form fields.","instance":"/oauth/token"} with WWW-Authenticate: Bearer realm="raia-portal-feed"'
  - 'GET /api/raia/portal/v1/listings/AE-PROBE (no token) -> 401 {"detail":"Missing Authorization: Bearer header."}'
  - 'GET /api/raia/portal/v1/branches/x/listings (no token) -> 401'
  - 'GET /api/raia/portal/v1/healthz -> 200 (security: [])'
  description: |-
    Server-to-server OAuth2 client credentials flow. The token endpoint is
    published by the implementer; credentials are issued out-of-band
    during onboarding. Tokens are short-lived Bearer JWTs.
  sources:
  - openapi/movehome-org-raia-portal-feed-openapi.yaml
  - https://github.com/MoveHome/MoveHome.Org/blob/main/docs/raia-portal-feed-api.md#3-authentication
  - https://github.com/MoveHome/MoveHome.Org/blob/main/src/app/oauth/token/route.ts
discovery:
  openid_configuration: {url: 'https://movehome.org/.well-known/openid-configuration', status: 404}
  oauth_authorization_server: {url: 'https://movehome.org/.well-known/oauth-authorization-server', status: 404}
  oauth_protected_resource: {url: 'https://movehome.org/.well-known/oauth-protected-resource', status: 404}
  jwks: {url: 'https://movehome.org/.well-known/jwks.json', status: 200, body: '{"keys":[]}'}
scopes_detail: scopes/movehome-org-scopes.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/movehome-org-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.